CVE

Id
11844  
CVE No.
CVE-2005-0638  
Status
Candidate  
Description
xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.  
Phase
Assigned (20050304)  
Votes
None (candidate not yet proposed)  
Comments